Program Removed

This program is no longer available on YesWeHack. The scope data shown below is historical and may not reflect the final state of the program.

keycloak-bug-bounty-program

YesWeHackView on YesWeHack
RawAI Enhanced
6
In Scope
5
Out of Scope
In-Scope Assets (6)
AssetCategoryBountyQuick Links
javascript client adapterOPEN-SOURCEYes-
javascript client adapterOTHERYes-
keycloak operatorOTHERYes-
keycloak operatorOPEN-SOURCEYes-
keycloak serverOTHERYes-
keycloak serverOPEN-SOURCEYes-
Out-of-Scope Assets (5)
AssetCategoryBounty
any asset that is not explicitly included in our program's scopeOTHERYes
any depreciated versions and other versions than the current stable/official version are considered out of scope except if specified otherwise in the program’s rulesOTHERYes
any local implementation of the project/implementation belonging to third partiesOTHERYes
any third parties’ or community’s assets that are not explicitly included (e.g. forks, libraries or packages)OTHERYes
experimental featuresOTHERYes
Scope Changes (30)
Mar 6, 2026
ChangeAssetCategoryScopeTime
Program Removed16:39
Feb 25, 2026
ChangeAssetCategoryScopeTime
Addedjavascript client adapterOPEN-SOURCEIn Scope19:08
Addedany asset that is not explicitly included in our program's scopeOTHEROut of Scope19:08
Addedany third parties’ or community’s assets that are not explicitly included (e.g. forks, libraries or packages)OTHEROut of Scope19:08
Addedany depreciated versions and other versions than the current stable/official version are considered out of scope except if specified otherwise in the program’s rulesOTHEROut of Scope19:08
Addedany local implementation of the project/implementation belonging to third partiesOTHEROut of Scope19:08
Addedexperimental featuresOTHEROut of Scope19:08
Addedkeycloak serverOPEN-SOURCEIn Scope19:08
Addedkeycloak operatorOPEN-SOURCEIn Scope19:08
Feb 22, 2026
ChangeAssetCategoryScopeTime
Addedjavascript client adapterOTHERIn Scope00:51
Addedany depreciated versions and other versions than the current stable/official version are considered out of scope except if specified otherwise in the program’s rulesOTHEROut of Scope00:51
Addedany local implementation of the project/implementation belonging to third partiesOTHEROut of Scope00:51
Addedexperimental featuresOTHEROut of Scope00:51
Addedkeycloak serverOTHERIn Scope00:51
Addedkeycloak operatorOTHERIn Scope00:51
Addedany asset that is not explicitly included in our program's scopeOTHEROut of Scope00:51
Addedany third parties’ or community’s assets that are not explicitly included (e.g. forks, libraries or packages)OTHEROut of Scope00:51
Feb 21, 2026
ChangeAssetCategoryScopeTime
Removedkeycloak serverOPEN-SOURCEIn Scope21:40
Removedkeycloak operatorOPEN-SOURCEIn Scope21:40
Removedjavascript client adapterOPEN-SOURCEIn Scope21:40
Removedany asset that is not explicitly included in our program's scopeOTHEROut of Scope21:40
Removedany third parties’ or community’s assets that are not explicitly included (e.g. forks, libraries or packages)OTHEROut of Scope21:40
Removedany depreciated versions and other versions than the current stable/official version are considered out of scope except if specified otherwise in the program’s rulesOTHEROut of Scope21:40
Removedany local implementation of the project/implementation belonging to third partiesOTHEROut of Scope21:40
Removedexperimental featuresOTHEROut of Scope21:40
Addedany third parties’ or community’s assets that are not explicitly included (e.g. forks, libraries or packages)OTHEROut of Scope00:33
Addedany depreciated versions and other versions than the current stable/official version are considered out of scope except if specified otherwise in the program’s rulesOTHEROut of Scope00:33
Addedany local implementation of the project/implementation belonging to third partiesOTHEROut of Scope00:33
Addedexperimental featuresOTHEROut of Scope00:33
Addedany asset that is not explicitly included in our program's scopeOTHEROut of Scope00:33